flow-nexus-swarm

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill manifest is primarily documentation for a cloud orchestration product and does not contain direct malicious code. However, it instructs users/agents to install and execute remote packages via npm/npx and to add an MCP integration into the Claude agent that may forward credentials and grant broad permissions. Those download-and-execute and transitive-install patterns are high-risk supply-chain vectors. The remote endpoints (flow-nexus.ruv.io, GitHub) may be legitimate, but the documentation lacks detailed secure-auth guidance and least-privilege constraints. Recommendation: treat this skill as suspicious until the flow-nexus package and MCP implementation are audited — avoid running npx/npm commands in privileged environments, inspect the package source (https://github.com/ruvnet/flow-nexus) before installing, and ensure explicit, scoped authentication flows and RBAC for execution streams and file listings.

Confidence: 78%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 05:46 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fagentic-flow%2Fflow-nexus-swarm%2F@ecba2a6dfcbe6010767dfb0a6daa9e9b1d6eed2b